First published: Tue Dec 01 2020(Updated: )
This release of Red Hat build of Quarkus 1.7.5 SP1 includes security updates, bug fixes, and enhancements. For more information, see the release notes page listed in the References section.<br>Security Fix(es):<br><li> hibernate-core: SQL injection vulnerability when both hibernate.use_sql_comments and JPQL String literals are used(CVE-2020-25638)</li> For more details about the security issues and their impact, the CVSS score, acknowledgments, and other related information see the CVE pages listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2020:5302 is classified as important due to the presence of security vulnerabilities.
To fix RHSA-2020:5302, update to the latest version of the Red Hat build of Quarkus, specifically 1.7.5 SP1.
RHSA-2020:5302 addresses a SQL injection vulnerability in hibernate-core which can potentially be exploited.
Even if you are not using hibernate-core, it is recommended to update to protect against other potential risks associated with the release.
RHSA-2020:5302 also includes bug fixes and enhancements alongside the security updates.